diff --git a/.gitignore b/.gitignore index 70485cdc..2c9c052d 100644 --- a/.gitignore +++ b/.gitignore @@ -49,3 +49,5 @@ handlers/texts.py .DS_Store Thumbs.db +nginx.conf +scripts/nginx.sh diff --git a/nginx.conf b/nginx.conf deleted file mode 100644 index 5c671969..00000000 --- a/nginx.conf +++ /dev/null @@ -1,105 +0,0 @@ -# Обработка HTTP-запросов, редирект на HTTPS -server { - listen 80; - server_name example.com; # Домен проекта - - location / { - # Перенаправление с HTTP на HTTPS - if ($arg_url != "") { - return 301 $arg_url; - } - - return 404 "URL-аргумент отсутствует"; - } -} - -# Обработка HTTPS-запросов (статический сайт и прокси) -server { - listen 443 ssl; - server_name example.com; # Домен проекта - - # SSL настройки - ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; # Путь к SSL-сертификату - ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem; # Путь к приватному ключу - include /etc/letsencrypt/options-ssl-nginx.conf; - ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; - - # Обработка подписок - location /sub { - proxy_pass http://localhost:3001; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - - add_header Content-Type text/plain; - add_header Content-Disposition inline; - add_header Cache-Control no-store; - add_header Pragma no-cache; - } - - # Статический сайт - root /var/www/website; # Путь к статическому сайту - index index.html; # Основной файл - - location / { - # Перенаправление с HTTP на HTTPS - if ($arg_url != "") { - return 301 $arg_url; - } - - return 404 "URL-аргумент отсутствует"; - } - - # Вебхуки из main.py - location /webhook { - proxy_pass http://localhost:3001/webhook; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - - proxy_connect_timeout 60s; - proxy_send_timeout 60s; - proxy_read_timeout 60s; - } - - # Вебхук Юкассы - location /yookassa/webhook { - proxy_pass http://localhost:3001/yookassa/webhook; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - - proxy_connect_timeout 60s; - proxy_send_timeout 60s; - proxy_read_timeout 60s; - } - - # Вебхук FreeCassa - location /freekassa/webhook { - proxy_pass http://localhost:3001/freekassa/webhook; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - - proxy_connect_timeout 60s; - proxy_send_timeout 60s; - proxy_read_timeout 60s; - } - - # Вебхук CryptoBot - location /cryptobot/webhook { - proxy_pass http://localhost:3001/cryptobot/webhook; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - - proxy_connect_timeout 60s; - proxy_send_timeout 60s; - proxy_read_timeout 60s; - } -} diff --git a/scripts/node.sh b/scripts/node.sh new file mode 100644 index 00000000..aee41eb3 --- /dev/null +++ b/scripts/node.sh @@ -0,0 +1,164 @@ +#!/bin/bash + +# Цвета для вывода +GREEN='\033[0;32m' +BLUE='\033[0;34m' +NC='\033[0m' # No Color + +echo -e "${BLUE}3x-ui Installation Script by izzzzzi${NC}" +echo "----------------------------------------" + +# Запрос данных у пользователя +read -p "Enter your domain (e.g., example.com): " DOMAIN +read -p "Enter desired admin panel port (default: 2053): " PANEL_PORT +read -p "Enter desired sub panel port (default: 2054): " SUB_PANEL_PORT + +# Использование значения по умолчанию для порта, если не указано +PANEL_PORT=${PANEL_PORT:-2053} +SUB_PANEL_PORT=${SUB_PANEL_PORT:-2054} + +# Создание необходимых директорий +echo -e "${GREEN}Creating directories...${NC}" +mkdir -p nginx/conf.d db cert + +# Установка certbot +echo -e "${GREEN}Installing certbot...${NC}" +apt-get update +apt-get install certbot -y + +# Остановка nginx если он запущен +echo -e "${GREEN}Stopping nginx if running...${NC}" +docker-compose down 2>/dev/null +systemctl stop nginx 2>/dev/null + +# Получение сертификата +echo -e "${GREEN}Obtaining SSL certificate...${NC}" +certbot certonly --standalone --agree-tos --register-unsafely-without-email -d $DOMAIN + +# Проверка успешности получения сертификата +if [ ! -d "/etc/letsencrypt/live/$DOMAIN" ]; then + echo "Failed to obtain SSL certificate. Please check your domain settings." + exit 1 +fi + +# Тестирование автообновления +echo -e "${GREEN}Testing certificate renewal...${NC}" +certbot renew --dry-run + +# Создание docker-compose.yml +echo -e "${GREEN}Creating docker-compose.yml...${NC}" +cat > docker-compose.yml << EOL +version: "3" + +services: + nginx: + image: nginx:alpine + container_name: nginx + ports: + - "80:80" + - "443:443" + volumes: + - ./nginx/conf.d:/etc/nginx/conf.d + - /etc/letsencrypt:/etc/letsencrypt + - /var/lib/letsencrypt:/var/lib/letsencrypt + networks: + - proxy-network + restart: unless-stopped + depends_on: + - 3x-ui + + 3x-ui: + image: ghcr.io/mhsanaei/3x-ui:latest + container_name: 3x-ui + hostname: ${DOMAIN} + volumes: + - \$PWD/db/:/etc/x-ui/ + - \$PWD/cert/:/root/cert/ + - /etc/letsencrypt:/etc/letsencrypt:ro + environment: + XRAY_VMESS_AEAD_FORCED: "false" + tty: true + networks: + - proxy-network + restart: unless-stopped + +networks: + proxy-network: + driver: bridge +EOL + +# Создание конфигурации Nginx +echo -e "${GREEN}Creating Nginx configuration...${NC}" +cat > nginx/conf.d/default.conf << EOL +server { + listen 80; + server_name ${DOMAIN}; + + location / { + return 301 https://\$host\$request_uri; + } +} + +server { + listen 443 ssl; + server_name ${DOMAIN}; + + ssl_certificate /etc/letsencrypt/live/${DOMAIN}/fullchain.pem; + ssl_certificate_key /etc/letsencrypt/live/${DOMAIN}/privkey.pem; + + ssl_protocols TLSv1.2 TLSv1.3; + ssl_prefer_server_ciphers off; + ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384; + + location / { + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + proxy_set_header Host \$http_host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header Range \$http_range; + proxy_set_header If-Range \$http_if_range; + proxy_redirect off; + proxy_pass http://3x-ui:${PANEL_PORT}; + } + + location /sub { + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + proxy_set_header Host \$http_host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header Range \$http_range; + proxy_set_header If-Range \$http_if_range; + proxy_redirect off; + proxy_pass http://3x-ui:${SUB_PANEL_PORT}; + } +} +EOL + +# Проверка наличия Docker и Docker Compose +if ! command -v docker &> /dev/null || ! command -v docker-compose &> /dev/null; then + echo -e "${GREEN}Installing Docker and Docker Compose...${NC}" + curl -fsSL https://get.docker.com | sh + curl -L "https://github.com/docker/compose/releases/download/v2.12.2/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose + chmod +x /usr/local/bin/docker-compose +fi + +# Настройка автообновления сертификатов +echo -e "${GREEN}Setting up certificate auto-renewal...${NC}" +cat > /etc/cron.d/certbot-renew << EOL +0 */12 * * * root certbot renew --quiet --deploy-hook "docker-compose -f $(pwd)/docker-compose.yml restart nginx" +EOL + +# Запуск сервисов +echo -e "${GREEN}Starting all services...${NC}" +docker-compose up -d + +echo -e "${GREEN}Installation completed!${NC}" +echo -e "${BLUE}You can access your 3x-ui panel at: https://${DOMAIN}${NC}" +echo -e "${YELLOW}Important: Default access to 3x-ui panel - ${NC}" +echo -e "${YELLOW}Login: admin${NC}" +echo -e "${YELLOW}Password: admin${NC}" +echo -e "${YELLOW}For security, it is recommended to change the password at: https://${DOMAIN}/panel/settings${NC}" +echo "Please wait a few minutes for all services to start properly." +echo "Default credentials can be found in the 3x-ui documentation." + +EOL \ No newline at end of file diff --git a/scripts/postgres.sh b/scripts/postgres.sh new file mode 100644 index 00000000..ed77314b --- /dev/null +++ b/scripts/postgres.sh @@ -0,0 +1,108 @@ +#!/bin/bash + +# Цвета для вывода +GREEN='\033[0;32m' +BLUE='\033[0;34m' +RED='\033[0;31m' +NC='\033[0m' # No Color + +echo -e "${BLUE}PostgreSQL Installation and Setup Script by izzzzzi${NC}" +echo "----------------------------------------" + +# Запрос данных у пользователя +read -p "Enter PostgreSQL port (default: 5432): " DB_PORT +read -p "Enter database name: " DB_NAME +read -p "Enter database user: " DB_USER +read -s -p "Enter database password: " DB_PASS +echo +read -s -p "Confirm database password: " DB_PASS_CONFIRM +echo + +# Проверка паролей +if [ "$DB_PASS" != "$DB_PASS_CONFIRM" ]; then + echo -e "${RED}Passwords do not match!${NC}" + exit 1 +fi + +# Использование значения по умолчанию для порта +DB_PORT=${DB_PORT:-5432} + +# Установка PostgreSQL +echo -e "${GREEN}Installing PostgreSQL...${NC}" +apt-get update +apt-get install -y postgresql postgresql-contrib + +# Остановка PostgreSQL для изменения конфигурации +systemctl stop postgresql + +# Настройка PostgreSQL для внешних подключений +echo -e "${GREEN}Configuring PostgreSQL...${NC}" + +# Настройка postgresql.conf +PG_VERSION=$(ls /etc/postgresql/) +PG_CONF="/etc/postgresql/$PG_VERSION/main/postgresql.conf" +PG_HBA="/etc/postgresql/$PG_VERSION/main/pg_hba.conf" + +# Backup конфигурационных файлов +cp $PG_CONF "${PG_CONF}.backup" +cp $PG_HBA "${PG_HBA}.backup" + +# Изменение postgresql.conf +sed -i "s/#listen_addresses = 'localhost'/listen_addresses = '*'/" $PG_CONF +sed -i "s/#port = 5432/port = $DB_PORT/" $PG_CONF + +# Изменение pg_hba.conf +cat > $PG_HBA << EOL +# TYPE DATABASE USER ADDRESS METHOD +local all postgres peer +local all all peer +host all all 127.0.0.1/32 md5 +host all all ::1/128 md5 +host all all 0.0.0.0/0 md5 +EOL + +# Запуск PostgreSQL +systemctl start postgresql +systemctl enable postgresql + +# Создание пользователя и базы данных +echo -e "${GREEN}Creating database and user...${NC}" +sudo -u postgres psql << EOF +CREATE USER $DB_USER WITH PASSWORD '$DB_PASS'; +CREATE DATABASE $DB_NAME OWNER $DB_USER; +ALTER USER $DB_USER WITH SUPERUSER; +EOF + +# Настройка файрвола +echo -e "${GREEN}Configuring firewall...${NC}" +if command -v ufw >/dev/null; then + ufw allow $DB_PORT/tcp + ufw status +fi + +# Проверка статуса PostgreSQL +systemctl status postgresql --no-pager + +echo -e "${GREEN}Installation completed!${NC}" +echo -e "${BLUE}PostgreSQL is running on port: ${DB_PORT}${NC}" +echo -e "${BLUE}Database name: ${DB_NAME}${NC}" +echo -e "${BLUE}Database user: ${DB_USER}${NC}" +echo "You can now connect to your database using:" +echo "psql -h localhost -p $DB_PORT -U $DB_USER -d $DB_NAME" +echo +echo "For remote connections use:" +echo "psql -h YOUR_SERVER_IP -p $DB_PORT -U $DB_USER -d $DB_NAME" +echo +echo -e "${RED}Important: Make sure to save these credentials in a secure place!${NC}" + +# Проверка подключения +echo -e "${GREEN}Testing connection...${NC}" +PGPASSWORD=$DB_PASS psql -h localhost -p $DB_PORT -U $DB_USER -d $DB_NAME -c "\conninfo" + +# Добавление информации о создании бэкапов +echo +echo "To create a backup, use:" +echo "pg_dump -h localhost -p $DB_PORT -U $DB_USER -d $DB_NAME > backup.sql" +echo +echo "To restore from backup, use:" +echo "psql -h localhost -p $DB_PORT -U $DB_USER -d $DB_NAME < backup.sql" \ No newline at end of file